)]}'
{
  "commit": "eb5640bc4445e7d7aaa913fddc34374b81d7a4f2",
  "tree": "cd6267eb88ab62bd151c8f4c438227d7de8981f1",
  "parents": [
    "a3aeea7c775d1859139394b57a105063351f0f5d"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Fri Feb 26 01:14:47 2021 -0500"
  },
  "committer": {
    "name": "CQ bot account: commit-bot@chromium.org",
    "email": "commit-bot@chromium.org",
    "time": "Fri Feb 26 21:07:18 2021 +0000"
  },
  "message": "Check the inner and outer CRL signature algorithms match.\n\nPer RFC5280, section 5.1.1.2,\n\n   [signatureAlgorithm] MUST contain the same algorithm identifier as the\n   signature field in the sequence tbsCertList (Section 5.1.2.2).\n\nThis aligns with a check we already do on the X.509 side.\n\nUpdate-Note: Invalid CRLs with inconsistent inner and outer signature\nalgorithms will now be rejected.\n\nChange-Id: I9ef495a9b26779399c932903871391aacd8f2618\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45946\nCommit-Queue: David Benjamin \u003cdavidben@google.com\u003e\nReviewed-by: Adam Langley \u003cagl@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "918f615bd31819af5351d4f6d96ccfb30e16b498",
      "old_mode": 33188,
      "old_path": "crypto/x509/x509_test.cc",
      "new_id": "210e57d803c69a660a9ea3540a1966cfa0227f3b",
      "new_mode": 33188,
      "new_path": "crypto/x509/x509_test.cc"
    },
    {
      "type": "modify",
      "old_id": "3b9f137ac2edea1cf744108f9ce27951e5cf7cce",
      "old_mode": 33188,
      "old_path": "crypto/x509/x_crl.c",
      "new_id": "cf13d5dad12b64a68b3f384520b6f07fd2de5f57",
      "new_mode": 33188,
      "new_path": "crypto/x509/x_crl.c"
    },
    {
      "type": "modify",
      "old_id": "89c100db5e3a20dc1403fbdf6c145e8e182b0d83",
      "old_mode": 33188,
      "old_path": "include/openssl/x509.h",
      "new_id": "357cf91942554c82502c4bc5a14f4f136dcd2e6b",
      "new_mode": 33188,
      "new_path": "include/openssl/x509.h"
    }
  ]
}
